Published:2026/09/14  Last Updated:2026/09/14

JVN#69877538
"YAMAP -Social Trekking GPS App" vulnerable to improper access control

Overview

Android application "YAMAP -Social Trekking GPS App" provided by YAMAP INC. contains an improper access control vulnerability related to its WebView implementation.

Products Affected

  • Android application "YAMAP -Social Trekking GPS App" versions v17.1.0 and earlier

Description

Android application "YAMAP -Social Trekking GPS App" provided by YAMAP INC. contains the following vulnerability:

  • Improper Verification of Source of a Communication Channel (CWE-940)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 5.1
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Base Score 5.4
    • CVE-2026-85125

Impact

The in-app browser may cause information leakage from the app or redirect users to unintended websites.

Solution

Update the Application
Update the application to the latest version according to the information provided by the developer.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Koki Sato of BroadBand Security, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-85125
JVN iPedia JVNDB-2026-000131